Revolut Leak Exposes Customers' Bitcoin (BTC) Transaction Records to Fake Government Request
Revolut leaked customer IDs, IBANs and Bitcoin transaction records to an attacker impersonating a government agency, stoking backlash against KYC rules.
AI SummaryAI
- Revolut disclosed customer data was leaked after a fake request from a genuine government domain.
- Leaked records included IBANs, account statements, withdrawal logs and full Bitcoin transaction histories.
- Revolut serves more than 70 million customers; the number of affected users remains undisclosed.
- ZachXBT said the affected users appear to have been selected for high net worth.
Revolut's Fake Government Request
Revolut, the UK-based digital bank serving more than 70 million customers worldwide, disclosed that it handed sensitive personal data to an unknown threat actor posing as a government agency. In a notification sent to affected customers, the company explained that it complied with an information request arriving from an unauthorized email address — one that nonetheless sat on a genuine government domain and carried valid domain-authentication credentials. That combination made the request look authentic, and the bank says it processed it in the reasonable belief that it originated from a real public authority. Which agency the impersonator pretended to be remains undisclosed. The shared records included names, dates of birth, occupations, mailing addresses, email addresses and phone numbers — enough on their own to endanger the personal safety of affected customers. Revolut also released images of passports and driving licenses paired with the facial-verification selfies submitted alongside them, creating a direct pathway to identity theft. Blockchain investigator ZachXBT assessed that the incident was likely limited in scale but observed that the affected users appear to have been selected for their high net worth, which raises the odds of follow-up attacks against them. Marc Zeller, founder of the now-dissolved Aave Chan Initiative, confirmed in a public post that he was among those affected, calling the leak a stark reminder that mandatory KYC rules have exposed many people to danger rather than delivered meaningful protection. His case is not an outlier: physical “wrench attacks” against crypto holders — including customers of card networks like Visa — have been climbing in both frequency and violence, and leaked address data makes such targeting far easier. The episode adds Revolut to a lengthening list of institutions and crypto firms that have inadvertently released customer files to impostors, deepening a global backlash against compulsory KYC collection.
a notification sent to affected customershttps://x.com/magicaltux/status/2098613398070305037
The technical scope of the exposure runs wider than the identity files. According to Arab BTC, the disclosure covered account statements and IBANs, account opening dates, wallet reference numbers that tie each customer to external wallet addresses, withdrawal logs and a complete transaction history — including the customer's Bitcoin transactions — along with the verification selfies. Revolut stressed that its biometric face-measurement data was not breached, but it has not said whether passwords, private keys or customer funds were affected, and it has yet to quantify how many customers had records released. Notably, this was not a direct hack of Revolut's infrastructure. The data left the bank through the dedicated channel the company maintains for government and law-enforcement information requests, weaponized by a single forged message. That distinction matters for remediation: there is no sign of a system-wide compromise to patch, and no evidence so far of funds moving. But it offers little comfort to customers whose financial histories, down to individual Bitcoin movements, are now in hostile hands. Transaction logs of that depth let an attacker reconstruct wealth, spot cash-out patterns and time an approach to a moment when the victim is likely holding hardware wallets or large balances at home. The records stop short of trading data such as order types, though for holders, withdrawal and transfer histories are typically the more dangerous exposure. Three questions remain open: which agency the attacker impersonated, how many customers were affected, and whether any compromised records translate into lost funds. The company has opened no public incident page beyond the direct notifications, leaving researchers to piece together the blast radius from individual disclosures. Readers tracking the market in real time can follow live spot and futures prices on Binance.
One Forged Email From Exposure
Taken together, the two disclosures trace one arc: centralized identity vaults are becoming the weakest link in the crypto stack. The primary records here — Revolut's own customer notification and the affected user's public post — describe a bank complying with a forged request, not a chain or exchange being broken. Unlike a replay attack or an on-chain exploit, nothing technical needed breaking; the attacker simply borrowed the authority of the state. In COINOTAG's reading, the lesson is procedural: law-enforcement request channels need out-of-band verification as rigorous as a withdrawal whitelist. Until KYC data is safeguarded with the same custody standards as customer assets, high-net-worth users remain one forged email away from exposure.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


